Question

Digital Ocean Ips hacking my site searching for wp-login from a various ip list of digital ocean

From last several days a list of various digital ocean ips are giving hits on my dedicated server on page wp-login.php, xmlrpc.php & other pages and the site is not using wordpress at all.
Ips:
162.243.162.24
46.101.18.90

Wordpress hackers are everywhere. I don’t run wordpress and get the same nonsense, and very little from Digital Ocean. Basically you will need to harden your web server to give the wordpress hackers a time out. Fail2ban for instance.

I have code in my webserver not to reply to any of the typical wordpress hacker requests. Unfortunately the hacker code is written so poorly that even if you do not reply, they keep requesting. Now the first step in fail2ban is to trap these wordpress hackers. Once you have them clearly delineated in the web server log, you can use fail2ban to filter them IP.

Wordfence is pretty good as a plugin it will block the ip after 3 attempts. There is an option for permanent ip block as well, it might be more user friendly than fail2ban, I actually think the plugin version of it is much less friendly than using it on a plain ubuntu server with nano. But that is just me I guess.

Harden the servers, definitely remove the version of apache you are using and any other server information you can hide as well as the version of word press you are using.
Run wp scan over your website or nikkto I think its called nikkto, but wp scan is good enough this will help tell you about the health of your plugins and if they have any known serious flaws, 90% of your hackers are script kiddies just wanting to learn how to use kali linux they are not a real threat and if you can stop them from using a lot of your sites resources then really they are not a problem more of a pest. Anyways good luck. wp scan is your friend!